Romania Proposes ANCOM as AI Act Market Watchdog & Contact
By Anthony Guerriero, Founder and lead analyst, The Leveraged Years.
Dateline: Bucharest, 12 March 2026. Last verified: 2026-07-25.
Most coverage of the EU Artificial Intelligence Act stops at Brussels. The part that decides who actually knocks on a company's door happens one country at a time, and it barely gets reported. Romania is a clean example. At the Government sitting of 12 March 2026, the cabinet took up a memorandum that answers the single most practical question a builder can ask about the AI Act in Romania: who enforces it here, and who do I call. The answer puts the national communications regulator, ANCOM, at the center.
What Romania proposed on 12 March 2026
The official press note listing the agenda of the 12 March 2026 sitting records the item under the memoranda section. The title is exact, and it maps straight onto Article 70 of the Regulation:
"MEMORANDUM cu tema: Desemnarea autoritatilor nationale competente si stabilirea punctului national unic de contact in ceea ce priveste aplicarea dispozitiilor Regulamentului (UE) 2024/1689 al Parlamentului European si al Consiliului din 13 iunie 2024 de stabilire a unor norme armonizate privind inteligenta artificiala (Regulamentul privind inteligenta artificiala)."
English gloss: "MEMORANDUM on the topic: Designation of the competent national authorities and establishment of the single national point of contact regarding the application of the provisions of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the Artificial Intelligence Regulation)."
Two things are being proposed in one instrument. First, the competent national authorities, meaning the bodies that would supervise and enforce the Regulation inside Romania. Second, the single national point of contact, which is the one address the European Commission, the AI Office, and other member states deal with when they need Romania to answer. The Act obliges every member state to stand both of these up. Romania has moved to do so through a Government memorandum on the cabinet agenda.
The competent-authority structure, and where ANCOM sits
ANCOM is not a data agency and it is not a new AI regulator. It is the Autoritatea Nationala pentru Administrare si Reglementare in Comunicatii, the telecoms and spectrum regulator. Its own communication on the framework describes the proposed role plainly, and it also names the other bodies that would share the load:
"prin Memorandum al Guvernului Romaniei, ANCOM a fost propusa sa exercite rolul de autoritate nationala de supraveghere a pietei si punct national unic de contact, alaturi de alte autoritati desemnate drept autoritati de supraveghere a pietei."
English gloss: "through a Memorandum of the Romanian Government, ANCOM was put forward to exercise the role of national market-surveillance authority and single national point of contact, alongside other authorities designated as market-surveillance authorities."
So Romania is not proposing to hand the whole Regulation to one super-regulator. The memorandum sets out a distributed model where sector supervisors keep their turf and ANCOM would carry the coordinating role plus the general market-surveillance function. From ANCOM's own account, the proposed split runs like this:
- ANCOM: national market-surveillance authority and single point of contact, and supervision in its existing lane of electromagnetic compatibility and radio equipment.
- Autoritatea de Supraveghere Financiara (ASF) and Banca Nationala a Romaniei (BNR): high-risk AI systems in financial services, where the system's placing on the market or use is directly tied to the provision of those financial services.
- Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP): high-risk AI in biometrics used for law enforcement, border management, and justice, plus high-risk systems in migration, asylum, border control, and the administration of justice and democratic processes.
- Sector authorities already designated at national level keep supervising AI in the areas they regulate under existing EU law.
If you build or deploy an AI system in Romania, the useful takeaway is that, under the proposal, your regulator would be decided by what your system does, not by a single AI desk. A credit-scoring model would answer to the financial supervisors. A biometric identification tool used at a border would answer to the data protection authority. The general market-surveillance backstop, and the coordinating contact point for the whole framework, would be ANCOM.
How Romania compares with other EU member states
The AI Act leaves the choice of authority to each country, so member states have landed in different places. Some created a dedicated agency, others handed the job to an existing regulator. Romania's telecoms-regulator route is one of the recognizable patterns.
| Member state | Lead or coordinating authority | Model | Source basis |
|---|---|---|---|
| Romania | ANCOM (market surveillance and single point of contact), with ASF, BNR, and ANSPDCP by sector | Existing telecoms regulator plus distributed sector supervisors | Government memorandum, sitting of 12 March 2026 |
| Portugal | ANACOM as an AI Act market-surveillance authority | Existing communications regulator | ANACOM designation, September 2025 |
| Spain | AESIA, the Agencia Espanola de Supervision de la Inteligencia Artificial | Purpose-built dedicated AI agency | Spanish agency created ahead of the Act |
The pattern worth noting is that two of these three, Romania and Portugal, put a communications regulator in the lead or market-surveillance seat, while Spain built a standalone body. Article 70 of the Regulation set 2 August 2025 as the point by which member states had to have their competent authorities in place. Romania's memorandum lands after that marker, which is exactly why the proposal is worth tracking rather than assuming it was settled on the EU timetable.
Key facts
- Instrument
- Government memorandum on the agenda of the 12 March 2026 sitting, proposing the competent national authorities and single national point of contact for Regulation (EU) 2024/1689.
- Issuer
- Government of Romania (Guvernul Romaniei).
- Event date
- 12 March 2026 (Government sitting).
- Who is proposed
- ANCOM as national market-surveillance authority and single point of contact, with ASF and BNR (financial services) and ANSPDCP (biometrics, migration, justice) as sector authorities.
- What it does
- Proposes how supervision and enforcement of the EU AI Act inside Romania would be assigned, and which body would serve as the single contact point for the Commission and other member states.
- Status
- Proposed via the Government agenda note and reflected in ANCOM's own framework communication; not yet an adopted act, and national institutional and penalty rules still to be set in law.
What this memorandum does NOT do
- It does not create new AI obligations. The substantive rules, risk classes, and duties come from Regulation (EU) 2024/1689 itself, which applies directly in Romania.
- It does not set fines. The Act frames the penalty ceilings, but the national sanctioning regime and the institutional organization still have to be established in Romanian law.
- It does not merge supervisors into one AI regulator. Romania kept a distributed model, so the responsible body depends on the sector and use of the system.
- It does not change deadlines in the Regulation. The AI Act's own application dates, including the prohibited-practice rules already in force from 2 February 2025 and the broader application milestone of 2 August 2026, run on the EU calendar regardless of this designation.
- It is not, on its own, a published law with an article number. It is a Government memorandum recorded on the cabinet agenda; treat the EU Regulation and any subsequent national act as the binding text.
FAQ
Which authority did Romania designate as its AI Act market-surveillance authority?
The memorandum on the agenda of the 12 March 2026 sitting proposes ANCOM, the national communications regulator, as a national market-surveillance authority and as the single national point of contact for the AI Act.
Is ANCOM the only Romanian authority named?
No. ANCOM shares the framework with sector supervisors: ASF and BNR for high-risk AI in financial services, and ANSPDCP for high-risk biometric, migration, and justice-related systems.
Does the memorandum create new penalties for AI systems?
No. It proposes authorities and the contact point. The penalty regime and institutional rules still have to be set in national law, and the obligations themselves flow from the EU Regulation.
Primary sources and related tracking
- Government of Romania, agenda press note for the sitting of 12 March 2026: gov.ro sitting note, 12 March 2026
- ANCOM, communication on the state of the AI Act framework in Romania: ANCOM framework note
- Track more national designations on our AI Regulation News hub.
- Related: Portugal designates ANACOM as an AI Act market-surveillance authority.